Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Tuesday, January 15, 2008

Ten Database Security Tips


As a direct marketer, I hear about database breaches and immediately think "BIG BUSINESS". I envision large financial institutions that collect data on millions of customers and imagine a scenario where stolen data results in large-scale lawsuits and identity theft mayhem. But, honestly, it's just as important (and perhaps even more important) for smaller businesses to ensure that their customer data is secure.

This article brings that point home: 10 Database Security Tips For Smaller Businesses

While storing sensitive or regulated information puts any company at risk, smaller businesses may have more to lose. "For small businesses, the impact of data loss is much higher, because they have less infrastructure," says Mark Kraynak, senior director of strategic marketing for Imperva. "They probably don't have backups, and they don't have the organizational wherewithal or response teams to handle a big public breach, or getting sued."

The article then proceeds to share ten solid tips that smaller businesses can follow to help keep their customer data secure.

I urge you to read the whole article, but I thought the following tips were especially solid.

Tip 5: Restrict Database Access -- both to the production database, as well as underlying hardware -- on a need-to-know basis.

Tip 6: Prohibit Wholesale Database Copying. A production database typically has a designated owner or gatekeeper. Yet who watches a database after it's been copied?

We see copies made and distributed all the time in the world of direct marketing. Someone requests a copy of the customer base to be used, for example, as a suppression file for an upcoming prospect mailing. The customer list is sent to an external data processing firm, perhaps. The campaign is implemented and no one ever thinks about that customer list again. Typically, nothing bad happens, but it takes only one instance of data theft.

We urge you to make sure that you have appropriate non-disclosure agreements in place with anyone who touches your data. Make sure that they specifically talk about how the processor must keep the data secure. That way, if something does happen, the fault will be on your processing vendor, and not on you.

Tip 7: Inventory Existing Databases: Locking down databases out of the box and prohibiting wholesale duplication may sound fine, but what about securing databases and copies that already are at large?

Companies must regularly find and inventory all existing databases. Know that one production database may hide many copies. "Typically, in a lot of businesses, you have the production database, but guess what, that database usually has a lot of copies -- developers have copies, for example -- and many databases correspond and make calls to each other," says Bowker.

Knowing where your data exists is a good thing for many reasons. Namely, if a data breach does occur, you'll be very well-positioned to find out where the theft happened in the first place. You'll also be well-prepared for any subsequent lawsuit showing that your firm has stringent practices in place to prevent data theft. A simple inventory of data assets goes a long way in showing that you do put a value on customer data and that you're serious about protecting it.

Overall, it may be time for firms, small and large alike, to put some serious thought into your database practices. News about a data breach is definitely the type of news we'd like to avoid in 2008!

Wednesday, September 26, 2007

Another Data Breach...


This time it's at Ameritrade, where 6.3 million customer records were compromised. Yesterday's DM News reported: Ameritrade lost 6.3 million names from database

"TD Ameritrade Holding Corporation, an online brokerage company, said one of its databases was hacked into and the personal information for more than 6.3 million customers was stolen. The company found malicious code in one of its databases."

These data breaches are happening all too often. In July, we posted about a data breach at Fidelity where a disgruntled employee stole over 2 million customer records.

Now, I do realize that it's extremely difficult to stop hackers and bad people (especially in-the-know employees). However, it's so important to the direct marketing industry that we nip this in the bud. If we intend to store customer information, we absolutely better ensure its safety. We need to invest in the right people, technology and practices to make it virtually impossible for the wrong people to access sensitive information.

If we don't do it, and do it now, I guarantee that some ambitious legislators will get involved. And, I think we all would agree that we don't need to work within more rules and legislation...

Friday, July 6, 2007

Data Breach at Fidelity

Sadly, the few times that our industry (direct marketing, data, lists) makes the news is when something bad happens. See "Direct Magazine's" article: Two-Million-Plus Names Stolen Data from Fidelity National Information Services.

Apparently a disgruntled (or just greedy) database admin decided that he, too, could get into the data business. He took a copy of 2.2 million Fidelity customers and sold the file to a direct marketing company/list broker. He was caught, fired and the data was recovered.

The original story reported over the last couple of days was that sensitive financial info was taken (not simply name and address). Did this ever make the bloggers fume, lashing out at everyone from the government to big business to (of course) junk mailers. Now it turns out that the stolen data only consisted of basic name/address info (still not a good thing, of course).

But the message I saw all over the Internet was that no one should EVER give their name and address out, or something really bad would happen to you. Identity theft, fraud, spying, etc. etc. Of course, all of these things CAN happen in today's information-rich times.

But, it's much more likely, for example, that the waiter who takes your credit card for dinner will sell that info to his friend than it is that a mail order company will jeopardize your private information. The mail order company understands that they need customers to stay in business...

Regardless, I believe that in these times, the onus is on direct marketers to be extremely sensitive to customer privacy. We need to make sure that each time we collect and use a piece of data that there is a valid benefit to the consumer. We shouldn't collect and store data just because we CAN collect that data.

And, as consumers, we should guard our personal data. We all know not to carry around our Social Security Cards. We make sure that the website we're ordering from is a reputable one, before we ever give out payment. We're onto the phishing scams and would never send any money to a strange African country, regardless of the huge payout promised.

But, there are times when it's very much in our best interest for businesses to understand things about us. When an airline remembers that you prefer an aisle seat, that's a good thing, right? Or, if your favorite restaurant sends you a free birthday dinner coupon, you're happy, correct?

Again, it all comes down to the fact that the stored data absolutely must bring value to the consumer or it needs to be deleted from the database. Yes, it is that simple :)